΢ÈíÒòÏòÓû§Ç¿¼Ó¸æ°×cookie±»·¨¹ú·£¿î6000ÍòÅ·Ôª
°ä²¼¹¦·ò 2022-12-26
¾ÝýÌå12ÔÂ22ÈÕ±¨Â·£¬·¨¹úÒþÖÔ¼à¹Ü»ú¹¹ÒѶÔÃÀ¹ú¿Æ¼¼¿Æ¼¼¹«Ë¾Î¢Èí´¦ÒÔ6000ÍòÅ·Ôª£¨6400ÍòÃÀÔª£©µÄ·£¿î£¬ÔÒòÊÇÆäÏòÓû§Ç¿¼Ó¸æ°×cookie¡£¹ú¶È¼¼ÊõºÍ×ÔÓÉίԱ»á(CNIL)°µÊ¾£¬Î¢ÈíµÄËÑË÷ÒýÇæBingδÉèÖÃÔÊÐíÓû§Ïñ½ÓÊÜcookieÒ»Ñùµ¥Ò»µØ»Ø¾øcookieµÄϵͳ¡£¸Ã¹«Ë¾Òѱ»´ÍÓëÈý¸öԵŦ·òÀ´¾ÀÕýÕâ¸öÎÊÌ⣬ÓâÆÚ»¹¿ÉÄÜÃæ¶ÔÿÌì60000Å·ÔªµÄ½øÒ»²½·£¿î¡£Î¢ÈíÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬ËüÔÚÕâÏîµ÷²éÆðͷ֮ǰ¾ÍÒѾ¶Ôcookie×ö·¨½øÐÐÁ˳Á´ó¸ü¸Ä¡£
https://www.securityweek.com/france-fines-microsoft-60-million-euros-over-advertising-cookies
2¡¢°Ä´óÀûÑÇÀ¥Ê¿À¼¿Æ¼¼´óѧÔâµ½Royal TeamµÄÀÕË÷¹¥»÷
ýÌå12ÔÂ22Èճƣ¬À¥Ê¿À¼¿Æ¼¼´óѧÔâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂУ԰´òÓ¡»ú´òÓ¡´óÁ¿µÄÊê½ð¼Í¼¡£QUT¸±Ð£³¤Margaret Sheil°µÊ¾ËýµÄ´òÓ¡»úÒ²Êܵ½Ó°Ï죬һÏòµØ´òÓ¡Êê½ð¼Í¼ֱµ½´òÓ¡»úÀïµÄÖ½Õźľ¡¡£Êê½ð¼Í¼³ÆÀ´×ÔRoyal ransomware£¬ËüÔÚÖ®Ç°ÖØÒª¹¥»÷ÃÀ¹úµÄÒ½ÁÆ»ú¹¹¡£×÷ΪÏìÓ¦´ëÊ©£¬À¥Ê¿À¼¿Æ¼¼´óѧÒѹعØËùÓÐITϵͳ£¬²¢¶Ô¸ÃÊÂÎñ·¢Õ¹µ÷²é¡£
https://www.abc.net.au/news/2022-12-22/qld-qut-cyber-attack-printers-royal/101802692
3¡¢ºÚ¿ÍÏúÊ۾ݳƴÓBetMGMÇÔÈ¡µÄ³¬¹ý150Íò¿Í»§µÄÊý¾Ý
¾Ý12ÔÂ22ÈÕ±¨Â·£¬ÌåÓý²©²Ê¹«Ë¾BetMGMÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬³Æ²¿Ãſͻ§µÄÓ×ÎÒÐÅϢй¶¡£¸Ã¹«Ë¾²¹³ä˵£¬ÆäÔÚ2022Äê11Ô·¢ÏÖ¸ÃÊÂÎñ£¬µ«¹¥»÷Ó¦¸ÃÊDzúÉúÔÚ2022Äê5Ô¡£ÃûΪbetmgmhackedµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳°ä²¼Êý¾ÝÏúÊ۵IJ¼¸æ£¬³ÆÆäÈëÇÖÁËBetMGMµÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬1569310ÌõÓû§¼Í¼£¬Éæ¼°ÃÜЪ¸ùÖÝ¡¢ÐÂÔóÎ÷ÖݺͰ²´ÖÂÔÊ¡µÈ¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢ºÍÉç»á°²È«ºÅÂëµÈÐÅÏ¢¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô·þÎñ¡£
https://securityaffairs.co/wordpress/139949/data-breach/betmgm-discloses-security-breach.html
4¡¢×êÑÐÍŶÓÅû¶ÆôÓÃksmbdµÄSMB·þÎñÆ÷µÄLinuxÄں˷ì϶
12ÔÂ25ÈÕ±¨Â·³Æ£¬×êÑÐÍŶÓÅû¶ÁËÒ»¸öÑϳÁµÄLinuxÄں˷ì϶£¨CVSSÆÀ·ÖΪ10£©£¬»áÓ°ÏìÆôÓÃÁËksmbdµÄSMB·þÎñÆ÷¡£¸Ã·ì϶´æÔÚÓÚSMB2_TREE_DISCONNECTºÅÁîµÄ´¦Öùý³ÌÖУ¬ÊÇÔÚ¶Ô¶ÔÏóÖ´ÐвÙ×÷֮ǰûÓÐÑéÖ¤¶ÔÏóµÄ´æÔÚ¶øµ¼Öµģ¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÄÚºËÖÐÖ´ÐÐËÁÒâ´úÂë¡£×êÑÐÈËÔ±²¹³ä·¡£Ê¹ÓÃSambaµÄSMB·þÎñÆ÷²»ÊÜÓ°Ï죬ʹÓÃksmbdµÄSMB·þÎñÆ÷ÈÝÒ×Êܵ½¶ÁÈ¡½Ó¼ûµÄÓ°Ï죬¿ÉÄÜй¶·þÎñÆ÷µÄÄڴ棨ÀàËÆÓÚHeartbleed·ì϶£©¡£½¨ÒéʹÓÃksmbdµÄÖÎÀíÔ±¸üе½8Ô°䲼µÄLinuxÄں˰汾5.15.61»ò¸ü¸ß°æ±¾¡£
https://securityaffairs.co/wordpress/140013/hacking/critical-linux-kernel-vulnerability.html
5¡¢Securonix·¢ÏÖÕë¶ÔÓ¡¶Èµ±¾ÖµÄ¹¥»÷»î¶¯STEPPY#KAVACH
¾Ý12ÔÂ23ÈÕ±¨Â·£¬Securonix·¢ÏÖÁËÕë¶ÔÓ¡¶Èµ±¾ÖµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯£¬²¢½«Æä¶¨ÃûΪSTEPPY#KAVACH¡£¸Ã»î¶¯Óë°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyµÄTTPÓÐËù³Áµþ£¬ÖØÒªÕë¶ÔÓ¡¶Èµ±¾Ö¹ÙԱʹÓõÄË«³É·ÖÉí·ÝÑéÖ¤½â¾ö¹æ»®Kavach¡£¹¥»÷ʼÓÚ´¹µö»î¶¯£¬¶øºóͨ¹ý.LNKÎļþÆô¶¯´úÂëÖ´ÐУ¬×îÖÕÏÂÔØ²¢ÔËÐжñÒâC# payload£¬³äÈÎÔ¶³Ì½Ó¼ûľÂí¡£Õâ²»ÊǵÚһ·Õë¶ÔKavachµÄ¹¥»÷£¬×Ô½ñÄêËêÊ×ÒÔÀ´£¬Transparent Tribe¾Íͨ¹ýKavachÖ÷ÌâµÄµö¶üÀûÓù¥»÷Ó¡¶È¡£
https://www.securonix.com/blog/new-steppykavach-attack-campaign/
6¡¢Wordfenceй©WP²å¼þ·ì϶CVE-2022-45359±»ÔÚÒ°ÀûÓÃ
WordfenceÔÚ12ÔÂ22ÈÕй©£¬ WordPress²å¼þYITH WooCommerce Gift Cards PremiumÖзì϶Òѱ»ÔÚÒ°ÀûÓ᣸÷ì϶׷×ÙΪCVE-2022-45359(CVSSÆÀ·ÖΪ9.8)£¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´ÔÚÒ×±»¹¥»÷µÄÍøÕ¾ÉÏ´«Îļþ£¬Ô̺¬Ìṩ¶Ô¸ÃÍøÕ¾ÆëÈ«½Ó¼ûȨÏÞµÄWeb shell¡£×êÑÐÈËÔ±³Æ£¬´óÎÞÊý¹¥»÷²úÉúÔÚ2022Äê11Ô£¬ÆäʱÖÎÀíÔ±ÉÐ佨¸´¸Ã·ì϶£¬µ«ÔÚ12ÔÂ14ÈÕÓÖ³öÏÖÁ˵ڶþ¸ö¶¥·å¡£´Ë±í£¬Ò»¸ö³ÁÒªµÄIPµØÖ·¶Ô10936¸öÍøÕ¾ÌáÒéÁË19604´Î¹¥»÷³¢ÊÔ¡£Ä¿Ç°·ì϶ÀûÓù¥»÷ÈÔÔÚ½øÐÐÖУ¬½¨ÒéʹÓøòå¼þµÄÓû§¾¡¿ìÉý¼¶µ½3.21°æ±¾¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/


¾©¹«Íø°²±¸11010802024551ºÅ